A new Travelodge room key security policy, now live across all 600-plus UK hotels, is the centrepiece of a sweeping safety review the company has disclosed alongside its 2024 financial results. The timing, and the circumstances that forced it, make comfortable reading for nobody.
Two separate incidents sit at the heart of this overhaul. The first took place at a Travelodge in Maidenhead, Berkshire, in December 2022, when an attacker obtained a key card to a victim’s room from a member of staff. BBC News reported the attacker was jailed for seven-and-a-half years in February following a sexual assault conviction. The second, reported by The Guardian, involved a woman being assaulted after staff gave a room key to her abuser, who had lied to obtain the card. That second incident triggered the independent review now under way.
Two incidents in which staff handed key cards to the wrong person. Both avoidable. The question is how a chain with over 13,000 employees across its hotels and support offices, welcoming roughly 22 million customers a year, managed to reach this point without a universal explicit-consent policy already in place.
What the Travelodge Room Key Security Changes Actually Involve
The policy changes Travelodge has announced are, in themselves, straightforward. Any additional or replacement room key now requires explicit permission from the guest staying in the room. That builds on an existing policy of never confirming to any third party that a guest is at one of its hotels. The company says the policy is now live across its entire estate, backed by training for its 12,000 customer-facing colleagues and supported by independent audit and mystery-shopper programmes.
Beyond the policy itself, the review has four visible strands. An independent inquiry led by Paul Greaney KC, a barrister specialising in public inquiries involving security, serious violent crime, and health and safety, is examining room access and escalation procedures. Management consultancy AlixPartners has been brought in to audit and reinforce the work underway. A partnership with a Violence Against Women and Girls expert is delivering senior leadership training. And a completed deadbolt audit across all UK rooms has confirmed that every key-card door carries a secondary deadbolt.
Travelodge is also participating in UKHospitality’s Guest Security Working Group, which has published its Guest Security Principles and Good Practice guidance covering room access procedures, guest privacy, and staff responsibilities. The UK government has welcomed those hospitality sector plans. The Caterer reports that UKHospitality had been developing the guidance since meeting government officials and sector operators in June to discuss how to improve hotel guest safety.
Revenue Held, But Profit Slipped as the Scandal Broke
The financial results released alongside the security disclosure tell their own story. According to the Travelodge investor site, Travelodge OpCo Group (Thame and London Limited) generated total underlying revenue of £1,037m in the year ended 31 December 2024, up fractionally from £1,035m in 2023. Comparable EBITDA, however, fell to £211.5m from £237.9m the prior year.
Customer numbers rose. Approximately 22 million guests stayed in 2024, roughly half a million more than in 2023, with around 90% of bookings made through direct channels including Travelodge’s own website. Chief Executive Jo Boydell described the 2024 performance as ‘solid,’ noting that occupancy slightly exceeded 2023 levels, though market rates were softer overall, particularly in London. The company also upgraded around 50% of its room estate during the year as part of a refit programme.
By conventional metrics, the business is functioning. More guests, more direct bookings, a four-dot average TripAdvisor score across UK hotels as of December 2024. But the EBITDA compression, in a year when the company was simultaneously managing a refit programme and an accelerating assault scandal, is a reminder that reputational pressure has real costs. A budget hotel chain’s core proposition is safety and reliability at an accessible price. Both are now under scrutiny.
My read is that the package of measures announced today is substantively reasonable. Explicit-consent key policies, independent legal oversight, management consultancy auditing, industry-wide guidance: these are the right levers. The real test is whether they are embedded deeply enough to change staff behaviour at the front desk at 11pm on a busy Friday. An independent review led by a King’s Counsel and mystery-shopper audits are a start. They are not, on their own, a conclusion. The Greaney report, when it lands, will set the bar.


